
Modrinth · Minecraft mod
CrashExploitFixer
This mod fixes a bunch of crash exploits discovered in Minecraft.
Quick answer
Which CrashExploitFixer release matches 26.1.2 Forge?
CrashExploitFixer forge-2.0.0+26.1.2 targets 26.1, 26.1.1, 26.1.2 with Forge. Do not install it on the client. It must be installed on the dedicated server. No extra mods listed for this file.
Where it goes
Is CrashExploitFixer required on the client, server, or both?
Do not install it on the client. It must be installed on the dedicated server.
This file is marked server-only.
What else does CrashExploitFixer forge-2.0.0+26.1.2 need?
forge-2.0.0+26.1.2 on 26.1.2 Forge. Every mod below is checked against that same setup.
This file does not list any required mods. Do not add a library just because a different file uses it.
This file does not list any required or optional mods.
Before you install it
Add CrashExploitFixer without breaking your instance.
Built for CrashExploitFixer forge-2.0.0+26.1.2 on 26.1.2 Forge. Pick another file and the loader, install side or required mods may change.
- 01
Stick to this file
Use forge-2.0.0+26.1.2. It targets 26.1, 26.1.1, 26.1.2 with Forge; another release may have different loader, side or dependency requirements.
- 02
Bring the mods it needs
This file does not list any required mods. Do not add a library just because a different file uses it.
- 03
Put it on the correct side
Do not install it on the client. It must be installed on the dedicated server.
- 04
Pick the file you checked
Use the “Get this file” button beside forge-2.0.0+26.1.2. It opens that exact file at the source.
About this project
What does CrashExploitFixer add?
CrashExploitFixer
The mod currently patches three different exploits for all affected Minecraft versions from 1.14.4 to Latest!
Entity Selector NBT Stack Overflow
A stack overflow vulnerability in Minecraft versions 1.14.4 through the latest release at the time of writing allows
attackers to crash servers by abusing deeply nested NBT data inside entity selectors, causing recursive parsing inTagParser to exhaust the JVM stack. While Minecraft 1.21.1 prevents unprivileged players from triggering the
issue through entity selectors, operators and creative-mode players can still reproduce the crash on unpatched servers.
Notably, PaperMC discovered and patched the underlying parser issue months earlier.
Blogpost from haykam: haykam.com
Excessive Network Object Allocation
A denial-of-service vulnerability affecting Minecraft networking allowed authenticated players to crash servers by
sending malicious packets that triggered excessive memory allocation during collection deserialization throughFriendlyByteBuf.readCollection, FriendlyByteBuf.readMap, or related methods. While the issue was exploitable
through a Fabric API packet and likely many modded packets across different loaders, NeoForge and Fabric patched the
issue for their most active versions (NeoForge: 1.21.1 and 26.1, Fabric: 1.20.1, 1.21.1, 1.21.11, 26.1, 26.2).
CrashExploitFixer patches the issue for all versions of Forge, NeoForge, and Fabric and is compatible with their fixes.
Many thanks to Paul for reporting this in private
Blogpost from NeoForge: neoforged.net
Translatable Component Expansion
A denial-of-service vulnerability affecting Minecraft 1.16 through 1.21.4 allowed attackers to craft recursively
expanding text components that could inflate into enormous strings during parsing, flattening, or calls such asComponent#getString(), leading to severe memory exhaustion and client or server soft-crashes. Newer research showed
that specially constructed hover-event payloads could trigger the issue without elevated permissions in vanilla
1.20.5–1.21.4. PaperMC had already protected against
this class of exploit for years, while modded environments remain especially vulnerable due to widespread use ofFriendlyByteBuf#readComponent() and related component deserialization paths in network packets.
Many thanks to Paul for reporting this in private
Project description from Modrinth.
Pick your setup
CrashExploitFixer by Minecraft version and loader
Choose the version and loader you play, then open the matching release.
26.2
2 loader builds26.1.2
4 loader builds26.1.1
4 loader builds26.1-rc-3
2 loader builds26.1
4 loader builds1.21.11-rc2
1 loader build1.21.11
4 loader builds1.21.10
4 loader builds1.21.9
4 loader builds1.21.8
4 loader builds1.21.7
4 loader buildsShowing the newest 12 of 47 game versions. Older files are in the list below.
Check the dependencies, then try the file in a copied instance before changing a world you care about.
Recent files
CrashExploitFixer versions and loaders
forge-2.0.0+26.1.2
crashexploitfixer-forge-2.0.0+26.1.2-all.jar
10 May 2026
Looking for an older file? The official Modrinth project page is in Resources.